Secunia - Stay Secure
Gartner
Home Corporate Website Jobs Updated Mailing Lists RSS Blog  Online Shop Advertise
Software Inspectors
  Scan Online
  Personal (PSI)
  Network (NSI 2.0)

Solutions For
  Security Professionals
  Security Vendors

Free Solutions For
  Open Communities
  Journalists & Media

Secunia Advisories
  Search
  Historic Advisories
  Listed By Product
  Listed By Vendor
  Statistics / Graphs
  Secunia Research
  Report Vulnerability
  About Advisories

Virus Information
  Chronological List
  Last 10 Virus Alerts
  About Virus Information

Secunia Customers
  Customer Area


Ubuntu update for thunderbird Advisory Available in German 

Secunia Advisory: SA29098  
Release Date: 2008-03-03
Last Update: 2008-03-07

Critical:
Highly critical
Impact: Security Bypass
Exposure of sensitive information
DoS
System access
Where: From remote
Solution Status: Vendor Patch

OS:Ubuntu Linux 6.06
Ubuntu Linux 6.10
Ubuntu Linux 7.04
Ubuntu Linux 7.10


CVE reference:CVE-2008-0304 (Secunia mirror)
CVE-2008-0412 (Secunia mirror)
CVE-2008-0413 (Secunia mirror)
CVE-2008-0415 (Secunia mirror)
CVE-2008-0418 (Secunia mirror)
CVE-2008-0420 (Secunia mirror)

Want to know the next time vulnerabilities are fixed in this product?
- Companies can be alerted via email and SMS!


Description:
Ubuntu has issued an update for thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or potentially compromise a user's system.

For more information:
SA28808
SA29133

Solution:
Apply updated packages.

-- Ubuntu 6.06 LTS --

Source archives:

http://security.ubuntu.com/ubuntu/poo...repatch080227-0ubuntu0.6.06.1.diff.gz
Size/MD5: 457207 42edc049dc6a57799c7762fd69519cef
http://security.ubuntu.com/ubuntu/poo...15~prepatch080227-0ubuntu0.6.06.1.dsc
Size/MD5: 1677 308921004b21abdec87e7193b1cc1855
http://security.ubuntu.com/ubuntu/poo...3+1.5.0.15~prepatch080227.orig.tar.gz
Size/MD5: 38264877 4266e1ff163ed81a555a6198a8c2fc45

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.6.06.1_amd64.deb
Size/MD5:3592366 d46ea4d2567ef29fe2e29d7ea59ebe0f
http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.6.06.1_amd64.deb
Size/MD5: 194738 d64dc9355993ee4e732db61ab7d18142
http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.6.06.1_amd64.deb
Size/MD5:59978 20504a6b397c381daaf6425c980241c9
http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.6.06.1_amd64.deb
Size/MD5: 12109986 e3f88ccf859f2cb0d4f5786ec84422f8

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/poo...epatch080227-0ubuntu0.6.06.1_i386.deb
Size/MD5:3585640 9a6fb88d3f7606c016694a56ac686c70
http://security.ubuntu.com/ubuntu/poo...epatch080227-0ubuntu0.6.06.1_i386.deb
Size/MD5: 188106 7b9b14a14e97870b209b8917b05d6899
http://security.ubuntu.com/ubuntu/poo...epatch080227-0ubuntu0.6.06.1_i386.deb
Size/MD5:55474 7fb01df26f2bb75b34370b547a9d2e5b
http://security.ubuntu.com/ubuntu/poo...epatch080227-0ubuntu0.6.06.1_i386.deb
Size/MD5: 10382740 287d5666f26e2cbe9cedf80236967480

powerpc architecture (Apple Macintosh G3/G4/G5):

http://security.ubuntu.com/ubuntu/poo...tch080227-0ubuntu0.6.06.1_powerpc.deb
Size/MD5:3591026 db402f32a02f27dd4a7e789da07e9667
http://security.ubuntu.com/ubuntu/poo...tch080227-0ubuntu0.6.06.1_powerpc.deb
Size/MD5: 191452 a879875dcd1075a9802e0a7cf5485ae6
http://security.ubuntu.com/ubuntu/poo...tch080227-0ubuntu0.6.06.1_powerpc.deb
Size/MD5:59076 9d4f1e4f5b2df85487d5cd767e42ca79
http://security.ubuntu.com/ubuntu/poo...tch080227-0ubuntu0.6.06.1_powerpc.deb
Size/MD5: 11661424 445a2d6d7df3c4c7aa20dc0a6772a283

sparc architecture (Sun SPARC/UltraSPARC):

http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.6.06.1_sparc.deb
Size/MD5:3587542 bc3561318d69fedc0f157ab5728a0545
http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.6.06.1_sparc.deb
Size/MD5: 188922 1a33f8b82f7dd1a6ec36a0fbfcf45894
http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.6.06.1_sparc.deb
Size/MD5:56976 572056a18fb37c374f201ec398583b2d
http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.6.06.1_sparc.deb
Size/MD5: 10855430 e4c3f65d7dd305e7567a5820133563e6

-- Ubuntu 6.10 --

Source archives:

http://security.ubuntu.com/ubuntu/poo...repatch080227-0ubuntu0.6.10.1.diff.gz
Size/MD5: 458362 a07bff4dbd70a88e0590a5eaf474b071
http://security.ubuntu.com/ubuntu/poo...15~prepatch080227-0ubuntu0.6.10.1.dsc
Size/MD5: 1677 a494c4c9b7dba82cfdd26b65618dacf7
http://security.ubuntu.com/ubuntu/poo...3+1.5.0.15~prepatch080227.orig.tar.gz
Size/MD5: 38264877 4266e1ff163ed81a555a6198a8c2fc45

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.6.10.1_amd64.deb
Size/MD5:3592214 8deae5034786195f9df37595ef8f9c66
http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.6.10.1_amd64.deb
Size/MD5: 194874 429fdb58bdce69d5b64163679c6721ad
http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.6.10.1_amd64.deb
Size/MD5:59988 c08085b641b26c1d11c81a3e2ea8a315
http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.6.10.1_amd64.deb
Size/MD5: 12102046 794b27b555370504f3c9d39d70fa0287

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/poo...epatch080227-0ubuntu0.6.10.1_i386.deb
Size/MD5:3589202 576af7e3d35db0291952f461b74f6bb0
http://security.ubuntu.com/ubuntu/poo...epatch080227-0ubuntu0.6.10.1_i386.deb
Size/MD5: 189532 81740cf1a82437340ded3dbf8d9bc668
http://security.ubuntu.com/ubuntu/poo...epatch080227-0ubuntu0.6.10.1_i386.deb
Size/MD5:56622 051f5aa4a749078227550fe4d8771759
http://security.ubuntu.com/ubuntu/poo...epatch080227-0ubuntu0.6.10.1_i386.deb
Size/MD5: 10842634 24a2f47129e13a115cb612ab7d6cf732

powerpc architecture (Apple Macintosh G3/G4/G5):

http://security.ubuntu.com/ubuntu/poo...tch080227-0ubuntu0.6.10.1_powerpc.deb
Size/MD5:3591066 8b12a9ffcc2d9d38198c4bbd19b08b76
http://security.ubuntu.com/ubuntu/poo...tch080227-0ubuntu0.6.10.1_powerpc.deb
Size/MD5: 191980 dc997f5ea64b0ce5225c08f737d6fab4
http://security.ubuntu.com/ubuntu/poo...tch080227-0ubuntu0.6.10.1_powerpc.deb
Size/MD5:59702 15afbb248986b685ef1f7ab59660e133
http://security.ubuntu.com/ubuntu/poo...tch080227-0ubuntu0.6.10.1_powerpc.deb
Size/MD5: 11792284 06f9647fb71deeee08d27451ecf38ae0

sparc architecture (Sun SPARC/UltraSPARC):

http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.6.10.1_sparc.deb
Size/MD5:3587556 6f575f6e24c7e004c71c3746895288f3
http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.6.10.1_sparc.deb
Size/MD5: 189390 227d5419c43080baf5316d6186246bc1
http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.6.10.1_sparc.deb
Size/MD5:57044 428a473e879f97fca358e49d363baa4c
http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.6.10.1_sparc.deb
Size/MD5: 11055900 f312edc01dbf038d5d4912e20bb2332e

-- Ubuntu 7.04 --

Source archives:

http://security.ubuntu.com/ubuntu/poo...repatch080227-0ubuntu0.7.04.1.diff.gz
Size/MD5: 128338 b8fd04ca331e279466c74ee642f37c9d
http://security.ubuntu.com/ubuntu/poo...15~prepatch080227-0ubuntu0.7.04.1.dsc
Size/MD5: 1677 f3d40a99a1bd698eb8793b05593ef9a1
http://security.ubuntu.com/ubuntu/poo...3+1.5.0.15~prepatch080227.orig.tar.gz
Size/MD5: 38264877 4266e1ff163ed81a555a6198a8c2fc45

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.7.04.1_amd64.deb
Size/MD5:3592572 cfd1788e37a527b5b421743a53ed6d4e
http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.7.04.1_amd64.deb
Size/MD5: 195362 1b39d27240963b06c8262159f65fecbb
http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.7.04.1_amd64.deb
Size/MD5:60482 7cfbfd6ac8e1f90b80f862b8da007cb7
http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.7.04.1_amd64.deb
Size/MD5: 12200898 98d6cadd4934398397d7efac96e5dfa2

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/poo...epatch080227-0ubuntu0.7.04.1_i386.deb
Size/MD5:3589906 52715181859839e6da06ee1d11e23b5b
http://security.ubuntu.com/ubuntu/poo...epatch080227-0ubuntu0.7.04.1_i386.deb
Size/MD5: 190018 2b4f148d9e1a17759b53a06d9bf10890
http://security.ubuntu.com/ubuntu/poo...epatch080227-0ubuntu0.7.04.1_i386.deb
Size/MD5:57116 71d8d8d39964a3c1812f169f9c97c5be
http://security.ubuntu.com/ubuntu/poo...epatch080227-0ubuntu0.7.04.1_i386.deb
Size/MD5: 10930196 0041f2ae1d9bb1cd903b928409b4b00e

powerpc architecture (Apple Macintosh G3/G4/G5):

http://security.ubuntu.com/ubuntu/poo...tch080227-0ubuntu0.7.04.1_powerpc.deb
Size/MD5:3593612 671ed2159590ee6b593c175d3264ae27
http://security.ubuntu.com/ubuntu/poo...tch080227-0ubuntu0.7.04.1_powerpc.deb
Size/MD5: 193502 00a290f2d5693deaaf563562bbce679c
http://security.ubuntu.com/ubuntu/poo...tch080227-0ubuntu0.7.04.1_powerpc.deb
Size/MD5:60476 b652ff1af4528c671b58c72edae91af8
http://security.ubuntu.com/ubuntu/poo...tch080227-0ubuntu0.7.04.1_powerpc.deb
Size/MD5: 12143668 5ba802316344128bf11cab16fefa8d8d

sparc architecture (Sun SPARC/UltraSPARC):

http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.7.04.1_sparc.deb
Size/MD5:3589116 d5ba04ed373c0d319707dd46f6451410
http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.7.04.1_sparc.deb
Size/MD5: 189836 7e1688245d345859a81b8985871b8016
http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.7.04.1_sparc.deb
Size/MD5:57538 084b7c136c7de9b5c873a0ded7260ee0
http://security.ubuntu.com/ubuntu/poo...patch080227-0ubuntu0.7.04.1_sparc.deb
Size/MD5: 11157146 15baa6c7a72ce11ca6131f999a99d5c5

-- Ubuntu 7.10 --

Source archives:

http://security.ubuntu.com/ubuntu/poo....12+nobinonly-0ubuntu0.7.10.0.diff.gz
Size/MD5: 126117 e8b5716234cd9a8c8f182cdec912570b
http://security.ubuntu.com/ubuntu/poo....0.0.12+nobinonly-0ubuntu0.7.10.0.dsc
Size/MD5: 1833 2633fee221a82874544f09df01be675f
http://security.ubuntu.com/ubuntu/poo...erbird_2.0.0.12+nobinonly.orig.tar.gz
Size/MD5: 34950360 c9d547a737eee9c928fa71e60970b06a

Architecture independent packages:

http://security.ubuntu.com/ubuntu/poo....12+nobinonly-0ubuntu0.7.10.0_all.deb
Size/MD5:59938 778a817e9ec45447c9dff6e7b2a3e456
http://security.ubuntu.com/ubuntu/poo....12+nobinonly-0ubuntu0.7.10.0_all.deb
Size/MD5:59924 87b966cf34b0432d7d96f8c55ec9324d

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/poo...2+nobinonly-0ubuntu0.7.10.0_amd64.deb
Size/MD5:3774602 6474009ecbd5ad94e54b29698e4254b5
http://security.ubuntu.com/ubuntu/poo...2+nobinonly-0ubuntu0.7.10.0_amd64.deb
Size/MD5:85108 909a71ed38a5475d8c1d578a6a1ced4e
http://security.ubuntu.com/ubuntu/poo...2+nobinonly-0ubuntu0.7.10.0_amd64.deb
Size/MD5: 12401230 67339270b6c346ddae25e50d024051e3

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/poo...12+nobinonly-0ubuntu0.7.10.0_i386.deb
Size/MD5:3763198 dfd33c657fca160377790ea9abbf8f02
http://security.ubuntu.com/ubuntu/poo...12+nobinonly-0ubuntu0.7.10.0_i386.deb
Size/MD5:80460 12be23055a62d2b59e384cb6b137e8b2
http://security.ubuntu.com/ubuntu/poo...12+nobinonly-0ubuntu0.7.10.0_i386.deb
Size/MD5: 10971856 b7d21ddfca19067a560da69994089fc6

powerpc architecture (Apple Macintosh G3/G4/G5):

http://security.ubuntu.com/ubuntu/poo...nobinonly-0ubuntu0.7.10.0_powerpc.deb
Size/MD5:3778306 13b230435fb89993e2a44fa8360b946b
http://security.ubuntu.com/ubuntu/poo...nobinonly-0ubuntu0.7.10.0_powerpc.deb
Size/MD5:83486 8c15623b3b28802a9c59430c32549a3e
http://security.ubuntu.com/ubuntu/poo...nobinonly-0ubuntu0.7.10.0_powerpc.deb
Size/MD5: 12248454 7c15fb75d956fd7229b35cc70bfb0bbd

sparc architecture (Sun SPARC/UltraSPARC):

http://security.ubuntu.com/ubuntu/poo...2+nobinonly-0ubuntu0.7.10.0_sparc.deb
Size/MD5:3759866 157589a4ae2cf8984d9e585e6e5658bf
http://security.ubuntu.com/ubuntu/poo...2+nobinonly-0ubuntu0.7.10.0_sparc.deb
Size/MD5:79860 b21a8ea3a55da0b176daa1be823fc2ad
http://security.ubuntu.com/ubuntu/poo...2+nobinonly-0ubuntu0.7.10.0_sparc.deb
Size/MD5: 11240626 bb5cc62a715f0985916f7be589764f71

Changelog:
2008-03-07: Updated "Solution" section with new packages for Ubuntu 6.06, 6.10, and 7.04 due to a regression. Added link to the "Original Advisory" section.

Original Advisory:
http://www.ubuntu.com/usn/usn-582-1
http://www.ubuntu.com/usn/usn-582-2

Other References:
SA28808:
http://secunia.com/advisories/28808/

SA29133:
http://secunia.com/advisories/29133/



Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.

298 Related Secunia Security Advisories, displaying 10

1. Ubuntu update for firefox
2. Ubuntu update for ruby1.8
3. Ubuntu update for kernel
4. Ubuntu update for samba
5. Ubuntu update for xorg-server
6. Ubuntu update for evolution
7. Ubuntu update for gnutls
8. Ubuntu update for openssh
9. Ubuntu update for ssl-cert
10. Ubuntu update for openssl

Show all related advisories


Send Feedback to Secunia

If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.








Secunia PSI
Scan | Patch | Track
Free Download

Secunia Poll

Do you think it's important to read Setup/User Guides for applications for use within your network?


See Results   


Most Popular Advisories

1.
Mozilla Firefox Multiple Vulnerabilities
2.
Opera for Windows Unspecified Code Execution
3.
Fedora update for glib2
4.
VLC Media Player WAV Processing Integer Overflow
5.
Mozilla Thunderbird Multiple Vulnerabilities
6.
GNOME Glib PCRE pcre_compile.c Buffer Overflow Vulnerability
7.
Opera Canvas Functions Information Disclosure
8.
PCRE pcre_compile.c Buffer Overflow Vulnerability
9.
UnixWare ReliantHA Privilege Escalation Vulnerabilities
10.
Drupal Organic groups Information Disclosure and Script Insertion





Vulnerability Management - Terms & Conditions - Copyright 2002-2008 Secunia - Compliance - Contact Secunia